Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-40062 |
|
Path Traversal in path-traversal (CVE-2026-40062)
path traversal in path-traversal (CVE-2026-40062). Confidential information can be exposed externally.
|
| CVE-2026-1726 |
|
Privilege Escalation in privilege-escalation (CVE-2026-1726)
vulnerability in privilege-escalation (CVE-2026-1726). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-39987 KEV |
|
[KEV] Vulnerability in Marimo remote-attack (CVE-2026-39987)
vulnerability in Marimo remote-attack (CVE-2026-39987). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2026-41134 |
|
Code Injection in kiota (CVE-2026-41134)
code injection in kiota (CVE-2026-41134). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.31.1` or later.
|
| CVE-2026-41650 |
|
Vulnerability in fast-xml-parser (CVE-2026-41650)
vulnerability in fast-xml-parser (CVE-2026-41650). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.7.0` or later.
|
| CVE-2026-41644 |
|
Vulnerability in github.com/monetr/monetr (CVE-2026-41644)
vulnerability in github.com/monetr/monetr (CVE-2026-41644). Confidential information can be exposed externally. Exploitable via `POST /api/lunch_flow/link`. Mitigation: upgrade to `1.12.5` or later.
|
| CVE-2026-41459 |
|
Vulnerability in path-traversal (CVE-2026-41459)
vulnerability in path-traversal (CVE-2026-41459). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34414 |
|
Path Traversal in path-traversal (CVE-2026-34414)
path traversal in path-traversal (CVE-2026-34414). Data can be tampered with by attackers.
|
| CVE-2026-34415 |
|
Vulnerability in path-traversal (CVE-2026-34415)
vulnerability in path-traversal (CVE-2026-34415). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34413 |
|
Vulnerability in path-traversal (CVE-2026-34413)
vulnerability in path-traversal (CVE-2026-34413). Data can be tampered with by attackers.
|
| CVE-2018-25269 |
|
Cross-Site Scripting (XSS) in icewarp (CVE-2018-25269)
cross-site scripting in icewarp (CVE-2018-25269). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-6857 |
|
Unsafe Deserialization in org.apache.camel:camel-infinispan (CVE-2026-6857)
vulnerability in org.apache.camel:camel-infinispan (CVE-2026-6857). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `4.20.0` or later.
|
| CVE-2026-35548 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-35548)
SSRF in ssrf (CVE-2026-35548). Confidential information can be exposed externally.
|
| CVE-2026-6862 |
|
Vulnerability in dos (CVE-2026-6862)
vulnerability in dos (CVE-2026-6862). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41651 |
|
Vulnerability in c (CVE-2026-41651)
vulnerability in c (CVE-2026-41651). Successful exploitation can lead to full system takeover. Exploitable via ``RUNNING``.
|
| CVE-2026-31476 |
|
Vulnerability in dos (CVE-2026-31476)
vulnerability in dos (CVE-2026-31476). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-6855 |
|
Path Traversal in path-traversal (CVE-2026-6855)
path traversal in path-traversal (CVE-2026-6855). Confidential information can be exposed externally. Exploitable via ``logs_dir``.
|
| CVE-2026-6844 |
|
Vulnerability in dos (CVE-2026-6844)
vulnerability in dos (CVE-2026-6844). Risk of unauthorized operations or information disclosure. Exploitable via ``readelf``.
|
| CVE-2026-6845 |
|
Vulnerability in dos (CVE-2026-6845)
vulnerability in dos (CVE-2026-6845). Risk of unauthorized operations or information disclosure. Exploitable via ``readelf``.
|
| CVE-2026-6846 |
|
Vulnerability in dos (CVE-2026-6846)
vulnerability in dos (CVE-2026-6846). Successful exploitation can lead to full system takeover.
|
| CVE-2026-6843 |
|
Vulnerability in dos (CVE-2026-6843)
vulnerability in dos (CVE-2026-6843). Risk of unauthorized operations or information disclosure. Exploitable via ``printf``.
|
| CVE-2026-40451 |
|
Cross-Site Scripting (XSS) in CVE-2026-40451 (CVE-2026-40451)
cross-site scripting in CVE-2026-40451 (CVE-2026-40451). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41458 |
|
Vulnerability in dos (CVE-2026-41458)
vulnerability in dos (CVE-2026-41458). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41457 |
|
SQL Injection in sqli (CVE-2026-41457)
SQL injection in sqli (CVE-2026-41457). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41144 |
|
Vulnerability in cpp (CVE-2026-41144)
vulnerability in cpp (CVE-2026-41144). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-33825 KEV |
|
[KEV] Vulnerability in Microsoft defender (CVE-2026-33825)
vulnerability in Microsoft defender (CVE-2026-33825). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2026-6832 |
|
Path Traversal in path-traversal (CVE-2026-6832)
path traversal in path-traversal (CVE-2026-6832). Data can be tampered with by attackers.
|
| CVE-2026-40906 |
|
SQL Injection in sqli (CVE-2026-40906)
SQL injection in sqli (CVE-2026-40906). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.5.0` or later.
|
| CVE-2025-70420 |
|
SQL Injection in sqli (CVE-2025-70420)
SQL injection in sqli (CVE-2025-70420). Successful exploitation can lead to full system takeover.
|
| CVE-2026-40923 |
|
Path Traversal in github.com/tektoncd/pipeline (CVE-2026-40923)
path traversal in github.com/tektoncd/pipeline (CVE-2026-40923). Risk of unauthorized operations or information disclosure. Exploitable via ``strings.HasPrefix``. Mitigation: upgrade to `1.0.2` or later.
|
| CVE-2026-41456 |
|
Cross-Site Scripting (XSS) in CVE-2026-41456 (CVE-2026-41456)
cross-site scripting in CVE-2026-41456 (CVE-2026-41456). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-40611 |
|
Path Traversal in path-traversal (CVE-2026-40611)
path traversal in path-traversal (CVE-2026-40611). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `4.34.0` or later.
|
| CVE-2026-21571 |
|
OS Command Injection in atlassian (CVE-2026-21571)
OS command injection in atlassian (CVE-2026-21571). Successful exploitation can lead to full system takeover.
|
| CVE-2025-41029 |
|
SQL Injection in sqli (CVE-2025-41029)
SQL injection in sqli (CVE-2025-41029). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-6750 |
|
Privilege Escalation in privilege-escalation (CVE-2026-6750)
vulnerability in privilege-escalation (CVE-2026-6750). Successful exploitation can lead to full system takeover.
|
| CVE-2026-31019 |
|
OS Command Injection in dolibarr (CVE-2026-31019)
OS command injection in dolibarr (CVE-2026-31019). Successful exploitation can lead to full system takeover.
|
| CVE-2025-10354 |
|
Cross-Site Scripting (XSS) in CVE-2025-10354 (CVE-2025-10354)
cross-site scripting in CVE-2025-10354 (CVE-2025-10354). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-32147 |
|
Path Traversal in path-traversal (CVE-2026-32147)
path traversal in path-traversal (CVE-2026-32147). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-3317 |
|
Cross-Site Scripting (XSS) in CVE-2026-3317 (CVE-2026-3317)
cross-site scripting in CVE-2026-3317 (CVE-2026-3317). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-13826 |
|
Vulnerability in dos (CVE-2025-13826)
vulnerability in dos (CVE-2025-13826). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-6058 |
|
Vulnerability in c (CVE-2026-6058)
vulnerability in c (CVE-2026-6058). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41245 |
|
Path Traversal in path-traversal (CVE-2026-41245)
path traversal in path-traversal (CVE-2026-41245). Data can be tampered with by attackers. Exploitable via ``LocalFolderExtractor``.
|
| CVE-2026-39918 |
|
Code Injection in CVE-2026-39918 (CVE-2026-39918)
code injection in CVE-2026-39918 (CVE-2026-39918). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34427 |
|
Vulnerability in privilege-escalation (CVE-2026-34427)
vulnerability in privilege-escalation (CVE-2026-34427). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34429 |
|
Cross-Site Scripting (XSS) in CVE-2026-34429 (CVE-2026-34429)
cross-site scripting in CVE-2026-34429 (CVE-2026-34429). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5966 |
|
Vulnerability in path-traversal (CVE-2026-5966)
vulnerability in path-traversal (CVE-2026-5966). Data can be tampered with by attackers.
|
| CVE-2026-5967 |
|
OS Command Injection in privilege-escalation (CVE-2026-5967)
OS command injection in privilege-escalation (CVE-2026-5967). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5963 |
|
SQL Injection in csharp (CVE-2026-5963)
SQL injection in csharp (CVE-2026-5963). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5964 |
|
SQL Injection in csharp (CVE-2026-5964)
SQL injection in csharp (CVE-2026-5964). Successful exploitation can lead to full system takeover.
|
| CVE-2024-7083 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2024-7083)
cross-site scripting in wordpress (CVE-2024-7083). Risk of unauthorized operations or information disclosure.
|